Vulnerabilities > Fedoraproject > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-06-10 | CVE-2020-35452 | Out-of-bounds Write vulnerability in multiple products Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. | 7.3 |
2021-06-10 | CVE-2021-26690 | NULL Pointer Dereference vulnerability in multiple products Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service | 7.5 |
2021-06-09 | CVE-2021-32677 | Cross-Site Request Forgery (CSRF) vulnerability in multiple products FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. | 8.1 |
2021-06-08 | CVE-2021-33571 | Server-Side Request Forgery (SSRF) vulnerability in multiple products In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. | 7.5 |
2021-06-08 | CVE-2021-22212 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products ntpkeygen can generate keys that ntpd fails to parse. | 7.4 |
2021-06-08 | CVE-2021-23169 | Out-of-bounds Write vulnerability in multiple products A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. | 8.8 |
2021-06-08 | CVE-2021-33560 | Information Exposure Through Discrepancy vulnerability in multiple products Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. | 7.5 |
2021-06-07 | CVE-2021-30521 | Out-of-bounds Write vulnerability in multiple products Heap buffer overflow in Autofill in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. | 8.8 |
2021-06-07 | CVE-2021-30522 | Use After Free vulnerability in multiple products Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2021-06-07 | CVE-2021-30523 | Use After Free vulnerability in multiple products Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet. | 8.8 |